CVE-2020-10701
published 2021-05-27CVE-2020-10701: A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.86%
54.8th percentile
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero, potentially leading to a denial of service. This flaw affects libvirt versions before 6.2.0.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 6.0.0-7 (bookworm) | libvirt 6.0.0-7 (bookworm) |
| msrc | cbl2_libvirt_7.10.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_libvirt_6.1.0-3_on_cbl_mariner_1.0 | — | — |
| redhat | libvirt | < 6.2.0 | 6.2.0 |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 6.0.0-7 | 6.0.0-7 |
| redhat | libvirt | >= 0 < 6.0.0-7 | 6.0.0-7 |
| redhat | libvirt | >= 0 < 6.0.0-7 | 6.0.0-7 |
| redhat | libvirt | >= 0 < 6.0.0-7 | 6.0.0-7 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the
vendor_msrc·2021-05-11·CVSS 6.5
CVE-2020-10701 [MEDIUM] CWE-862 A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero potentially leading to a denial of service. This flaw affects libvirt versions before 6.2.0.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who c
Red Hat
libvirt: guest agent timeout can be set under read-only mode leading to DoS
vendor_redhat·2020-03-20·CVSS 6.5
CVE-2020-10701 [MEDIUM] CWE-862 libvirt: guest agent timeout can be set under read-only mode leading to DoS
libvirt: guest agent timeout can be set under read-only mode leading to DoS
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero, potentially leading to a denial of service. This flaw affects libvirt versions before 6.2.0.
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout.
Debian
CVE-2020-10701: libvirt - A missing authorization flaw was found in the libvirt API responsible for changi...
vendor_debian·2020·CVSS 6.5
CVE-2020-10701 [MEDIUM] CVE-2020-10701: libvirt - A missing authorization flaw was found in the libvirt API responsible for changi...
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero, potentially leading to a denial of service. This flaw affects libvirt versions before 6.2.0.
Scope: local
bookworm: resolved (fixed in 6.0.0-7)
bullseye: resolved (fixed in 6.0.0-7)
forky: resolved (fixed in 6.0.0-7)
sid: resolved (fixed in 6.0.0-7)
trixie: resolved (fixed in 6.0.0-7)
GHSA
GHSA-rhq9-pr9r-9x2j: A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout
ghsa_unreviewed·2022-05-24
CVE-2020-10701 [MEDIUM] CWE-862 GHSA-rhq9-pr9r-9x2j: A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero, potentially leading to a denial of service. This flaw affects libvirt versions before 6.2.0.
OSV
CVE-2020-10701: A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout
osv·2021-05-27·CVSS 6.5
CVE-2020-10701 [MEDIUM] CVE-2020-10701: A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero, potentially leading to a denial of service. This flaw affects libvirt versions before 6.2.0.
No detection rules found.
No public exploits indexed.
2021-05-27
Published